cbcvebase.
CVE-2020-1934
published 2020-04-01

CVE-2020-1934: In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

PriorityP345medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
51.95%
98.8th percentile
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

Affected

24 ranges
VendorProductVersion rangeFixed in
apacheapache_http_server
apachehttp_server2.4.0 – 2.4.41
apachehttpd
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianapache2< apache2 2.4.43-1 (bookworm)apache2 2.4.43-1 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
opensuseleap
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oracleenterprise_manager_ops_center
oracleinstantis_enterprisetrack17.1 – 17.3
oraclezfs_storage_appliance_kit

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via mod_proxy_ftp when Apache HTTP Server proxies requests to a malicious FTP backend server; monitor for unexpected FTP proxy traffic through Apache.
  • The attack vector is remote over HTTP; a remote attacker could exploit this to obtain sensitive information (uninitialized memory disclosure) via a malicious FTP backend.
  • ·Affected Apache HTTP Server versions are 2.4.0 through 2.4.41; the fix is included in 2.4.42 and later. Ensure mod_proxy_ftp is disabled if FTP proxying is not required.
  • ·Red Hat JBoss Enterprise Web Server 2 is not affected; Red Hat Enterprise Linux 5 and 6 are out of support scope; Red Hat Software Collections fix was deferred at time of advisory.
  • ·The vulnerability is caused by use of an uninitialized memory variable; in most cases there is no practical impact, but corner cases may allow remote reading of memory contents.

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_apache5.3LOW
vendor_debian5.3LOW
vendor_oracle5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.